NVIDIA NVIDIA

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any NVIDIA product.

RSS Feeds for NVIDIA security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018

NVIDIA Gpu Display Driver78 vulnerabilities

NVIDIA Triton Inference Server58 vulnerabilities

NVIDIA Virtual Gpu Manager46 vulnerabilities

NVIDIA Cuda Toolkit44 vulnerabilities

NVIDIA Nemo33 vulnerabilities

NVIDIA Geforce26 vulnerabilities

NVIDIA Tesla25 vulnerabilities

NVIDIA Jetson22 vulnerabilities

NVIDIA Geforce Experience18 vulnerabilities

NVIDIA Megatron Lm11 vulnerabilities

NVIDIA Gpu Driver7 vulnerabilities

NVIDIA Cumulus Linux3 vulnerabilities

NVIDIA Mlnx Os3 vulnerabilities

NVIDIA Onyx3 vulnerabilities

NVIDIA Aistore3 vulnerabilities

NVIDIA Bluefield1 vulnerability

Nvidia Gpu Operator1 vulnerability

NVIDIA Quadro1 vulnerability

NVIDIA Runai1 vulnerability

NVIDIA Skyway1 vulnerability

NVIDIA Studio1 vulnerability

NVIDIA Titan V Firmware1 vulnerability

NVIDIA Connectx1 vulnerability

NVIDIA Cv Cuda1 vulnerability

NVIDIA Igx1 vulnerability

NVIDIA Isaac Lab1 vulnerability

NVIDIA Jetson Linux1 vulnerability

Nvidia Container Toolkit1 vulnerability

NVIDIA Mellanox Os1 vulnerability

NVIDIA Metrox 21 vulnerability

NVIDIA Metrox 3 Xc1 vulnerability

NVIDIA Nsight Graphics1 vulnerability

NVIDIA Nvapp1 vulnerability

NVIDIA Nvdebug Tool1 vulnerability

Nvidia App1 vulnerability

Recent NVIDIA Security Advisories

Advisory Title Published
5860 Security Bulletin: NVIDIA Triton Inference Server - August 2026 August 4, 2026
5842 Security Bulletin: NVIDIA Dynamo - August 2026 August 4, 2026
5857 Security Bulletin: NVIDIA DCGM Exporter - July 2026 July 28, 2026
5815 Security Bulletin: NVIDIA Networking Bluefield, ConnectX - July 2026 July 28, 2026
5869 Security Bulletin - NVIDIA - Transformers4Rec - July 2026 July 21, 2026
5840 Security Bulletin: NVIDIA TensorRT-LLM - July 2026 July 14, 2026
5853 Security Bulletin: NVIDIA Triton Inference Server - July 2026 July 14, 2026
5855 Security Bulletin: NVIDIA TensorRT - July 2026 July 14, 2026
5841 Security Bulletin: NVIDIA Megatron Bridge - June 2026 June 30, 2026
5849 Security Bulletin: NVIDIA AIStore Framework - June 2026 June 30, 2026

By the Year

In 2026 there have been 158 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in NVIDIA in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.




Year Vulnerabilities Average Score
2026 158 7.40
2025 174 6.74
2024 34 6.81
2023 28 6.22
2022 43 6.70
2021 75 6.54
2020 35 6.78
2019 16 6.90
2018 7 5.50

It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent NVIDIA Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-47623 Aug 04, 2026
Deserialization-RX Vulnerability in NVIDIA Dynamo Linux NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47622 Aug 04, 2026
NVIDIA Dynamo for Linux Sensitive Data Exposure via Error Messages NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47621 Aug 04, 2026
NVIDIA Dynamo Linux Race Condition in LoRA Manager Singleton NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47620 Aug 04, 2026
NVIDIA Dynamo LoRA Manager Singleton Race Condition (Linux) NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CVE-2026-47619 Aug 04, 2026
NVIDIA Dynamo_Linux Examples/Recipes RCE & DoS Vulnerability NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2026-47618 Aug 04, 2026
SSRF in NVIDIA Dynamos Rust multimodal media fetcher NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47617 Aug 04, 2026
NVIDIA Dynamo SSRSF via DNS Rebinding NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47616 Aug 04, 2026
SSRF in NVIDIA Dynamo for Linux media fetch leads to info disclosure NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47615 Aug 04, 2026
NVIDIA Dynamo SSFR via crafted URL in multimodal request NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47614 Aug 04, 2026
NVIDIA Dynamo SSRF Vulnerability (CVE-2026-47614) NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47613 Aug 04, 2026
NVIDIA Dynamo Improper Pathname Restriction Leading to Info Disclosure NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47612 Aug 04, 2026
NVIDIA Dynamo Image Loader: Improper Path Restriction (CVE-2026-47612) NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-24255 Aug 04, 2026
NVIDIA Dynamo Cache Hash Collision Enables Data Tampering NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CVE-2026-24254 Aug 04, 2026
NVIDIA Dynamo OOB Write in multimodal serving topology (priv esc, DoS) NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVE-2026-24253 Aug 04, 2026
NVIDIA Dynamo Linux Out-of-Bounds Write Exploitable for DoS NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47487 Aug 04, 2026
NVIDIA Triton Inference Server Path Traversal MLflow PLG NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Triton Inference Server
CVE-2026-47483 Jul 28, 2026
Unauth Resource Exhaustion via /debug/pprof in NVIDIA DCGM Exporter NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVE-2026-24252 Jul 27, 2026
OS Command Injection in NVIDIA NeMo for Linux NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
Nemo
CVE-2026-24232 Jul 21, 2026
Deserialization RCE in NVIDIA Transformers4Rec NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24272 Jul 14, 2026
TensorRT Heap Buffer Overflow Vulnerability NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24268 Jul 14, 2026
NVIDIA TensorRT Heap Buffer Overflow (CVE-2026-24268) Allows Code Execution NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24238 Jul 14, 2026
NVIDIA TensorRT Improper Array Index Validation Allows Code Execution NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24227 Jul 14, 2026
Untrusted Deserialization in NVIDIA TensorRT Code Exec (CVE-2026-24227) NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24271 Jul 14, 2026
NVIDIA TensorRT-LLM GPU Allocation Exhaustion via OpenAI API NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-47475 Jul 14, 2026
TensorRTLLM OpenAI API Assertion Trigger Leads to DoS NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-47470 Jul 14, 2026
NVIDIA TensorRT-LLM gRPC Chat API CWE-20 Local Attack NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-24226 Jul 14, 2026
Improper Control of Code Generation in NVIDIA TensorRTLLM Leads to Code Execution NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24259 Jul 14, 2026
Missing Auth in NVIDIA TensorRT-LLM Critical Function (CVE-2026-24259) NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24220 Jul 14, 2026
Unsafe ZeroMQ Deserialization in NVIDIA TensorRT-LLM VisualGen NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24234 Jul 14, 2026
NVIDIA TensorRT-LLM SSRF via Media Fetching (CVE-2026-24234) NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVE-2026-24229 Jul 14, 2026
NVIDIA TensorRT-LLM Disaggregated Orchestrator Allows Full Cluster State Access NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CVE-2026-47473 Jul 14, 2026
TensorRT-LLM Write-What-Where Vulnerability Enables Data Tampering NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-47471 Jul 14, 2026
NVIDIA TensorRT-LLM Heap-Based Buffer Overflow via Tensor Deserialization NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.
CVE-2026-47472 Jul 14, 2026
NVIDIA TensorRT-LLM IPC deserialization flaw allows local code execution NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
CVE-2026-24233 Jul 14, 2026
TensorRT-LLM Restricted Unpickler Deserialization Exploit (Code Exec) NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-47482 Jul 14, 2026
Memory Leak in NVIDIA Triton Inference Server Causes DoS NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47481 Jul 14, 2026
NVIDIA Triton Inference Server Auth Bypass via Alternate Channel NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Triton Inference Server
CVE-2026-47480 Jul 14, 2026
DDoS via Uncaught Exception in NVIDIA Triton Inference Server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47479 Jul 14, 2026
DoS via Resource Exhaustion in NVIDIA Triton Inference Server (Linux) NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47478 Jul 14, 2026
NVIDIA Triton Server DoS via expired FD abuse NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47477 Jul 14, 2026
NVIDIA Triton Inference Server Stack Buffer Overflow CVE-2026-47477 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47476 Jul 14, 2026
NVIDIA Triton Inference Server Uncontrolled Resource DoS NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24270 Jul 01, 2026
NVIDIA AIStore Auth Bypass CVE-2026-24270 NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Aistore
CVE-2026-24266 Jul 01, 2026
UAF in NVIDIA Triton Inference Server (Linux) NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24264 Jul 01, 2026
NVIDIA Triton Inference Server DoS via High Compression Exploit NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24251 Jul 01, 2026
Code Execution via Improper Resource Control in NVIDIA Megatron Bridge on Linux NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24250 Jul 01, 2026
NVIDIA Megatron Bridge for Linux: Improper Input Validation Leading to Code Execution NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24249 Jul 01, 2026
NVIDIA Megatron Bridge Deserialization Flaw CVE-2026-24249 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24248 Jul 01, 2026
Improper Code Generation in NVIDIA Megatron Bridge for Linux NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24247 Jul 01, 2026
Deserialization Flaw in NVIDIA Megatron Bridge (Linux) NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.